M365Clarity · MSP

Microsoft 365 MSP multi-tenant management — audit every client tenant at scale

M365Clarity · 24 June 2026

← All articles

The MSP Microsoft 365 audit problem

If you manage Microsoft 365 for ten or more clients, you already know the problem. Keeping track of what is configured, what has drifted, and what is missing across every tenant is either a manual process that consumes hours per client, or it simply doesn't happen between quarterly reviews.

The consequence is configuration drift. A client tenant that was clean at onboarding quietly accumulates gaps — an admin account without MFA, external forwarding left open, Intune compliance policies with a 30-day grace period that nobody reduced. None of these trigger alerts. They just sit there until something goes wrong.

What MSPs are typically checking manually

Most MSPs rely on a combination of Microsoft 365 Lighthouse, individual admin centre spot checks, and spreadsheet-based audit templates. The problem with each approach:

What a structured multi-tenant audit covers

A thorough Microsoft 365 audit across MSP clients should cover 131 configuration checks across six areas:

The most common finding across MSP client tenants: External email forwarding enabled with no block policy, and admin accounts with permanent Global Administrator roles where PIM eligibility would reduce risk significantly.

How M365Clarity works for MSPs

M365Clarity's Multi-Tenant MSP tier lets you connect and manage multiple client tenants from a single portal. Each client tenant is connected once using delegated Microsoft Graph permissions — read-only, no agents, no scripts. Once connected, you can trigger a full 131-check scan for any client in 30 seconds and see the results immediately.

The portfolio view shows all client tenants in one place with a RAG (Red, Amber, Green) status summary for each. You can see at a glance which clients have critical findings, which are clean, and which haven't been scanned recently.

Each tenant's detailed view covers all six areas above with plain-English findings, remediation steps, and AI-generated setup guides for any feature that needs enabling.

What this replaces: 45–90 minutes of manual admin centre checks per client per quarter, replaced by a 30-second scan with a structured, consistent output you can use in QBRs and client reports.

Using scan results in client conversations

One of the most practical uses of structured tenant scanning is in quarterly business reviews. Rather than presenting a generic M365 health update, you can show a client exactly which of their licensed features are configured, which are unused, and what the risk profile looks like in plain terms they understand.

Clients who see their own red findings — especially around identity and email security — are significantly more likely to approve remediation work and security uplift projects. The data creates the conversation rather than requiring the MSP to make the case from scratch.

New client onboarding

The scan is particularly valuable at new client onboarding. Rather than spending the first week manually exploring an inherited tenant, a 30-second scan gives you an immediate structured view of the configuration state. You know within minutes whether you've inherited a clean environment or one with significant gaps to address.

M365Clarity MSP — multi-tenant portal

Connect your client tenants, scan in 30 seconds per tenant, and manage the configuration view across your entire client base from one portal. White-label PDF reports included.

View MSP pricing →

Related articles